Hacking PSA: Reports of Fusee gelee patched units in the wild

  • Thread starter Deleted-442439
  • Start date
  • Views 85,701
  • Replies 315
  • Likes 10
D

Deleted-442439

Guest
OP
The funny thing is that RCM can still be accessed.
I don't know, once emunand is here...

Emunand alone is useless without a exploit to boot from the sd. If you have one of the patched units and updated to 5.x you will not be able to run emunand.
 
  • Like
Reactions: Kioku

morrison22

Well-Known Member
Member
Joined
Nov 26, 2005
Messages
618
Trophies
0
XP
1,948
Country
United States
Source: https://www.resetera.com/threads/bootrom-patched-switches-appear-at-retail.54531/

As many know, nVidia had an "oopise" with 10-years worth of SoCs which suffered from an unpatchable, critical bootloader flaw that allowed arbitrary code to be run in recovery mode (RCM) at boot, forfeiting any security on the system. This flaw affected the entire Tegra line and its predecessors going back 10 years. (As many have failed to properly delineate, RCM is not the actual flaw. It is just a standard recovery mode for fixing broken Switches.)

This flaw was found in the Switch by fail0veflow and reported last year. This flaw led to a boom in homebrew progress and development, but of course this allowed for malware piracy groups to create and market piracy mod-chips to load payloads at boot in RCM and hjack the system. And roughly 18million switches are vulnerable to that flaw. (This has resulted in large ban waves for pirates, some bricked switches from stupid people bridging the wrong pins and frying their motherboards, to DRMed piracy dongles with stolen community code and brickcode in them... because why not? To all sorts of other nonsense and bullshit, such as hacking. And of course, a lot of emulator work and good old-fashioned homebrew.)

To the surprise of no one, Nintendo (and nVidia) have rolled out an updated hardware that is fixed from this arbitrary write-flaw through a system known as iPatches. These are fuses with specific bits of code that fix flaws in the boot processes and other hardware level operations. These cannot be applied after leaving the factory (as the fuse allowing them to be written or edited is blown).

What does this mean?

Well it means that the bootflaw is no longer a viable path and so now it becomes a question of software exploits in the kernel/system and updating once again starts to close exploits. (So if you bought that dongle, its useless if you run out of old Switches.) Now you have to face Nintendo's rather secure kernel but because these units were actually made some time ago they still (some) come with 4.0.1 which still has a software flaw, known at Deja Vu in the community (again, thanks to nVidia… because why stop at a hardware flaw when your entire GPU driver stack can be compromised). This flaw was largely patched as of 5.0.0 and is being held for the eventual Mariko Switch (which isn't out yet, and this change isn't said revision). It is unlikely that this flaw will be released until Mariko or until a firmware patch completely closes it as it is our only path currently known into reaching TrustZone and bypassing Nintendo's rather tight security.

This iPatch fix likely occurred many months ago but we're only now seeing it at retail. Because it ships with 4.0.1 and not 5.x, you can date the time of manufacture to very early this year, so Nintendo was on top of the flaw after its submission by f0f.

Long Story Short: If you want a homebrew-able Switch, buy one now and do not update to 5.x.

If you send in for repair, you'll get a replaced SoC.
 
Last edited by morrison22,

Monkiky

Member
Newcomer
Joined
Apr 12, 2018
Messages
10
Trophies
0
Age
24
XP
148
Country
Mexico
Guess it always pays off to buy a console as early as possible, huh?
Even if all units were vulnerable for over a year...
 
D

Deleted-442439

Guest
OP
So those +20 millions can update normally to new FW?

Yes, all old models can update as much as they want and Fusee Gelee will always work.

However: Softmods are only possible on 4.1.0 and under. For coldboot you need to be on 3.0.1 or lower.
 
  • Like
Reactions: yahoo

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,010
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,163
Country
United States
This announcement seems premature if it's based on a few individual cases of anecdotal evidence.
Is it really though? Granted, if we give it a few months we'll probably see more cases like it. However, it makes perfect sense to start seeing them.
 
D

Deleted-442439

Guest
OP
Is it really though? Granted, if we give it a few months we'll probably see more cases like it. However, it makes perfect sense to start seeing them.

Agreed, although we have not dumped anything from newer units yet it makes sense for them to start entering the wild, and in the cases I have observed several cables and PC's were tried without luck, so something was guaranteed to be patched.
 
  • Like
Reactions: Kioku

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
This announcement seems premature if it's based on a few individual cases of anecdotal evidence.

This is pretty normal for retail delay. Manufacturing of these probably started many moons ago, but you have to shift what's already at the front of retail channels out of the channels before the new units arrive to the front. In some areas, this happens faster than others. Japan will see this before the US, it may have even started weeks ago but we just never knew because no one checked and/or spoke English.

If you're seeing units now and given the current rate of Switch sales/shipments, it will be impossible to find an old OG Switch on store shelves by the end of the month to next month unless you live in a completely dead area. Once things have reached the front of retail, it means back channels are completely switched over.

You're now seeing the last vestiges of finite supply of OG Switches.

Its not 20 million, by the by, since the shipment figure would include whatever has also been in back channel for months of these units. Its likely around 16-18 million.
 
Last edited by V-Temp,

VzUh

you are now reading my custom title
Member
Joined
Feb 5, 2017
Messages
354
Trophies
0
Location
inside me
XP
385
Country
Spain
I'll just leave this here
Ktemkin'ss Fusee Gelee's Disclosure Pdf said:
Recommended Mitigations[...]For a device already in consumer hands, no solution is proposed [...] It is suggested that consumers be made aware of the situation so they can move to other devices, where possible.
The time to be good guys has come;)
 

kitzuki

Well-Known Member
Member
Joined
Jan 29, 2008
Messages
132
Trophies
1
XP
1,055
Country
United States
I have 3 switch consoles 2 bought at launch and one i got 2 weeks ago. So i wonder if this a region thing for now because the one I just got in the US is fine.
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
I have 3 switch consoles 2 bought at launch and one i got 2 weeks ago. So i wonder if this a region thing for now because the one I just got in the US is fine.

Units are produced in Asia, backchannel turn over will be seen first there. It then will balloon out to adjacent markets then further and further, etc.

We don't really have any idea when this exactly started just that someone *now* found a unit for this purpose that didn't work.

Once you see it, it doesn't take long for it to be everywhere within a few weeks as stock turns over and new supplies are shipped in, and we don't know when this started since no one was fastidiously checking every shipment ever.
 
Last edited by V-Temp,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    SylverReZ @ SylverReZ: @K3Nv2 https://www.youtube.com/watch?v=9yWIobzBdKc